Data processing agreement.
This is our current published policy. For contractual agreements (DPA, MSA), contact hello@cyfriq.com.
This page is an overview of how Cyfriq processes personal data on behalf of its customers. It is not itself the contract. The signed Data Processing Agreement (DPA) is a contractual document that forms part of our Master Services Agreement — to receive it for signature, email hello@cyfriq.com.
Controller and processor roles
When a customer uses the Cyfriq product, the customer determines the purposes and means of processing the personal data it puts into the platform. The customer therefore acts as the data controller (or, where the customer is itself processing on behalf of its own customers, as a processor), and Cyfriq acts as the processor (or sub-processor). Cyfriq processes customer personal data only on the customer's documented instructions and for the purpose of providing the service.
Scope of processing
The categories of data subjects and personal data, the nature and purpose of the processing, and its duration are determined by the customer's own use of the product and are set out in the signed DPA. In general, Cyfriq processes the data necessary to deliver identity and access management, data loss prevention, cloud security, behaviour analytics and the related security functions the customer has enabled.
Security measures
Cyfriq maintains technical and organisational measures designed to protect customer data, including:
- Encryption of data in transit and at rest.
- Logical tenant isolation so that one customer's data is separated from another's.
- Access controls on the principle of least privilege, with multi-factor authentication for administrative access.
- Audit logging and monitoring of access to production systems.
- Secure development, change-management and vulnerability-management practices.
Where we hold independent certifications or attestations, they are listed in our Trust Center.
Sub-processors
Cyfriq may engage sub-processors to help deliver the service — for example, infrastructure hosting. Each sub-processor is engaged under a written contract imposing data-protection obligations equivalent to those in our DPA. A current list of sub-processors is available on request, and the signed DPA sets out how we give notice of, and how customers may object to, changes.
International transfers and residency
Customer data is processed in an India region, supporting data-residency requirements under Indian law. Where any processing outside India is required, it is carried out under the safeguards described in the signed DPA and consistent with applicable law.
Assistance with data-subject requests
Taking into account the nature of the processing, Cyfriq provides reasonable assistance to enable the customer, as controller, to respond to requests from data subjects to exercise their rights of access, correction, erasure and the like.
Personal data breach notification
Cyfriq will notify the affected customer without undue delay after becoming aware of a personal data breach affecting that customer's data, and will provide the information reasonably needed to allow the customer to meet its own notification obligations.
Return and deletion of data
On termination or expiry of the service, and at the customer's choice, Cyfriq returns or deletes the customer's personal data in accordance with the timelines set out in the signed DPA, unless retention is required by law.
Audits
Cyfriq makes available the information reasonably necessary to demonstrate compliance with its processing obligations, and supports audits within the scope and process defined in the signed DPA.
How to obtain the signed DPA
This overview does not create contractual rights on its own. To receive the executable Data Processing Agreement for review and signature, contact hello@cyfriq.com and we will share the current version.
Questions?
For any question about how we process customer data, contact us at hello@cyfriq.com.